'Net Features : amazon ec2http://www.websitemagazine.com/content/blogs/posts/archive/tags/amazon+ec2/default.aspxTags: amazon ec2enCommunityServer 2008 SP2 (Build: 31104.93)China’s Web Outage: Defense against the Risk of Third-Party Serviceshttp://www.websitemagazine.com/content/blogs/posts/archive/2014/04/03/china-s-web-outage-defense-against-the-risk-of-third-party-services.aspxThu, 03 Apr 2014 15:00:00 GMT1e469e21-c924-44fa-a132-47b5d0a8ad47:32400Administrator0http://www.websitemagazine.com/content/blogs/posts/rsscomments.aspx?PostID=32400http://www.websitemagazine.com/content/blogs/posts/archive/2014/04/03/china-s-web-outage-defense-against-the-risk-of-third-party-services.aspx#comments<p>By Heiko Specht, <a href="http://www.compuware.com/en_us/application-performance-management.html" target="_blank">Compuware APM Center of Excellence</a></p>
<hr />
<p>On Tuesday, January 21, one of the biggest outages in history&mdash;if not the world&rsquo;s largest outage&mdash;happened to the Internet in China. Essentially, the Internet went completely dark for one of the strongest and fastest growing economies for one full business day. Since succeeding in China is a top priority for many companies, this outage impacted organizations from all corners of the world. Not only were revenues lost, but organizations took a huge hit to their brands and were seen as unresponsive, even if these organizations had nothing to do with causing the outage. What&rsquo;s more, global advertisers lost significant investments as major consumer-facing Chinese websites cascaded downward.</p>
<p>Though major outages like this are nothing new, they&rsquo;ve actually increased in frequency in the past year. Major technology players from Microsoft to Apple&rsquo;s iCloud service to Amazon EC2 have all experienced major outages since this past summer, resulting in unplanned downtime for consumers and businesses alike. One would think that massive investments in technology infrastructures would have the effect of minimizing service disruptions like these, or at least containing them. But they haven&rsquo;t. The truth is, these outages and their widespread collateral damage signify the escalating dangers of an increasingly interconnected and complex Web world. More specifically, the China outage serves as a perfect case-in-point of something that&rsquo;s becoming increasingly obvious: the perils of relying so heavily on third-party services and applications interwoven into modern websites.</p>
<h2>What Exactly Happened?</h2>
<p>At around 3 p.m. local time on January 21, two-thirds of all domain requests in China were routed to a single IP address in Wyoming, which promptly collapsed under load. This was believed to be a domain name system (DNS) attack, the biggest of its type in history. Not all domains were affected; mainly it was those ending in .com and .net, while those ending in .com.cn were partially affected.</p>
<p><img style="float:right;border:1px solid black;margin:5px;" src="http://www.websitemagazine.com/images/blog/PayPal-Marks.png" width="266" height="142" alt="" />Unfortunately, even most of the Chinese websites that were not directly impacted also ended up going down. Here&rsquo;s why: many of the affected domains were hosts to third-party services relied upon by thousands of Chinese websites. One example is analytics engines. Never mind that the analytics engines weren&rsquo;t working, meaning that companies lost out on a whole day&rsquo;s worth of data that could have been used to increase conversions. That was just the tip of the iceberg. Like dominoes, these &ldquo;poisoned&rdquo; third-party services brought down the websites they were feeding into, even those websites that were not directly affected by the attack. Another third-party service that went dark was PayPal. This meant that any website integrating PayPal on its back-end could not process transactions for a full eight hours, which was a moot point anyway because these websites were likely inaccessible.</p>
<p>If third-party services make a website so vulnerable, why use them? Like it or not, for most companies, third-party services are here to stay. It&rsquo;s far easier to sign a contract with an advertising firm to help optimize the display of ads on a site, than to try and design such a system internally. Items such as analytics, social media, Web fonts and popular JavaScript libraries are often drawn from services that websites don&rsquo;t directly control, but rely on to work efficiently and reliably at all times. When these external services have an issue, it&rsquo;s the website owner that takes the hit to revenues and reputation, not the third party. In fact, according to some estimates, organizations only control one-third of the time required to load a page, as the rest is consumed by third-party services and content that are not within an organization&rsquo;s direct control.&nbsp;</p>
<h2>Lessons Learned</h2>
<p>In this era of increased dependence on third-party services, is there anything organizations can do to experience the benefits while protecting and insulating their Web performance? Fortunately, with certain approaches, the negative impact of major Web service outages can be mitigated. For example:</p>
<p style="padding-left:30px;">&bull;<span> </span>Organizations need to be better about getting ahead of website performance issues: Given all the performance-impacting elements standing between the data center and the end user &ndash; e.g. the cloud, CDNs, ISPs, devices and browsers &ndash; the end-user perspective is the only reliable vantage point from which to gauge performance. New generation application performance management (APM) tools can deliver this view, and it&rsquo;s important to work with technology providers that provide performance views across key geographies and user segments.</p>
<h3>Organizations must closely evaluate and monitor third-party services</h3>
<p>Before a third-party service is enlisted, organizations should carefully test its performance. One way is to compare website performance before a third-party service is added and afterward, in order to gauge the overall performance impact. If a performance degradation is identified, organizations must work with the third-party service to resolutely fix the problem, before the service is implemented.</p>
<p>Monitoring third-party services in production is also important in order to validate service level agreements (SLAs), but also to identify third-party performance issues as they occur and take appropriate action. As the China example illustrates, the &ldquo;ripple effect&rdquo; of third-party performance issues is often unavoidable. But that doesn&rsquo;t mean the impact can&rsquo;t be thwarted or minimized. When a serious performance problem is detected, organizations should have contingency plans in place so that offending third-party services can quickly be removed. While they can be extremely valuable when performing well, many third-party services (such as analytics) are not worth having if it means frustrating customers.</p>
<h3>The end-user experience needs to be top-of-mind in all third-party service decisions</h3>
<p>In general, websites should keep third-party services to a minimum. Organizations always need to ask themselves before adding a third-party service, if the added feature/functionality is worth the potential increase in overall vulnerability and lost conversions. In this vein, there needs to be constant communication between performance monitoring teams, and the teams who request and depend on these third-party services. This is the key to making the smartest decisions that will protect and promote revenues above all else.</p>
<p>Additionally, when a third-party service is implemented, there are certain design steps organizations can take to proactively reduce risk exposure. For example, by understanding the load order of elements on a site and making sure third-party services and applications are on the bottom, organizations can protect and enhance perceived customer load time, even when a third-party service does suddenly go awry.</p>
<p>As a final note here, to ensure better performance for feature-rich websites and applications, many organizations rely on content delivery networks (CDNs) strategically located in key geographies. Ironically, CDNs represent another third-party service and another potential point of failure, especially since they&rsquo;re likely serving multiple customers experiencing &ldquo;flash&rdquo; traffic events. Here, again, measuring performance from the true end-user perspective on the other side of a CDN, is critical to protecting and maximizing these investments.&nbsp;</p>
<h3>Leverage industry resources</h3>
<p>Free services such as Outage Analyzer can identify third-party service outages and the corresponding regional impacts (see image). For example, around the 2013 holiday season, Outage Analyzer identified one third-party outage that impacted hundreds of domains. Services like this may not prevent major outages from happening, but they can help organizations at least see when a widespread performance issue is not their own, and give them a head start in putting contingency plans into place and communicating proactively with customers.</p>
<p><img style="vertical-align:middle;margin:5px;" src="http://www.websitemagazine.com/images/blog/outage-analyzer_screenshot.png" width="600" height="422" alt="" /></p>
<h3>Prepare for the unexpected</h3>
<p>Kaifu Lee, Google&rsquo;s former China head, recently wrote: &ldquo;To have a chance in China, the American company must empower the local team to be responsive, autonomous, localized and ready for combat.&rdquo; Indeed, the Chinese market is huge, tough and hypercompetitive, and the recent outage likely left many global companies feeling as if their hands were tied. The lax reaction by the international media only served to downplay the significance of the event to those beyond China&rsquo;s physical borders. But make no mistake, the hit to revenues and brand to companies around the world was huge.&nbsp;</p>
<p>To a certain extent, major Web events like the one that just happened in China are unavoidable. But the fact is, it&rsquo;s just one more example of the little &ldquo;Internet storms&rdquo; that are brewing all the time, and the subsequent impact on modern websites. Fortunately, this impact can be anticipated, contained and minimized with the right approaches. As Kaifu Lee implies, organizations must be prepared for the unexpected and refuse to cede ultimate responsibility for their website success, wherever they may be doing business.</p>
<hr />
<p>Heiko Specht is a technology expert at the <a href="http://www.compuware.com/en_us/application-performance-management.html" target="_blank">Compuware APM Center of Excellence</a>.</p>
<div style="clear:both;"></div><img src="http://www.websitemagazine.com/content/aggbug.aspx?PostID=32400" width="1" height="1">amazon ec2PayPal Accesswmfeaturewm-designdevdomain name system attackApple’s iCloudChinese websitesChina Web outageDNS AttackInternet outageOutage AnalyzerCompuware APM Center of ExcellenceHigh Storage Instances Come to Amazon EC2http://www.websitemagazine.com/content/blogs/posts/archive/2012/12/28/high-storage-instances-come-to-amazon-ec2.aspxFri, 28 Dec 2012 21:09:00 GMT1e469e21-c924-44fa-a132-47b5d0a8ad47:22599Michael Garrity0http://www.websitemagazine.com/content/blogs/posts/rsscomments.aspx?PostID=22599http://www.websitemagazine.com/content/blogs/posts/archive/2012/12/28/high-storage-instances-come-to-amazon-ec2.aspx#comments<hr />
<p><strong><a href="http://aws.amazon.com/" target="_blank">Amazon Web Services (AWS)</a> wanted to give its <a href="http://aws.amazon.com/ec2/" target="_blank">Elastic Compute Cloud (EC2)</a> users a present, and what better way to celebrate the holidays than with family &ndash; a new instance family, that is.</strong><br /><br />The cloud computing services provider from Amazon recently announced High Storage instances for EC2. This additional instance family is optimized for applications that required rapid access to large amounts of data, while also providing AWS customers with 35 EC2 Compute Units of computing capacity, 117 GiB of RAM and 48 TB of storage across 24 hard disk drives. Moreover, these instances are capable of delivering more than 2.4 GB of sequential I/O performance per second.<br /><br />In other words, because High Storage instances provide such massive amounts of direct attached storage per instance, they are ideal for data-intensive applications like Hadoop workloads, log processing, data warehousing and parallel file systems for processing and analyzing large datasets in the AWS cloud.<br /><br />High Storage instances follow eight other EC2 instance families, including Cluster Compute and High I/O instances, to help meet the evolving application requirements of Amazon EC2 customers. Like the others, High Storage instances were designed to enhance the performance and efficiency of even the most demanding applications. They also power the new petabyte-scale data warehousing service Amazon Redshift and can help Amazon Elastic MapReduce customers process larger quantities of data more resourcefully, who helps significantly lower costs.<br /><br />AWS customers can immediately launch High Storage instances through the AWS Management Console, Amazon EC2 and Elastic MapReduce Command Line Interfaces, AWS SDKs and various other third-party libraries. However, at the moment this new instance family is only available in the US East Region; they will be made available in other AWS Regions &ldquo;in the coming months.&rdquo;</p>
<p>&nbsp;</p>
<div style="clear:both;"></div><img src="http://www.websitemagazine.com/content/aggbug.aspx?PostID=22599" width="1" height="1">Web Hostingamazoncloud computingamazon web servicescloudamazon ec2awswm-webhostinginstance familyhigh storage instancesSpot Instances in Amazon EC2http://www.websitemagazine.com/content/blogs/posts/archive/2009/12/14/spot-instances-in-amazon-ec2.aspxMon, 14 Dec 2009 14:42:00 GMT1e469e21-c924-44fa-a132-47b5d0a8ad47:11422Pete Prestipino0http://www.websitemagazine.com/content/blogs/posts/rsscomments.aspx?PostID=11422http://www.websitemagazine.com/content/blogs/posts/archive/2009/12/14/spot-instances-in-amazon-ec2.aspx#comments<p><b>Amazon Web Services announced Spot Instances, a new option for purchasing and consuming Amazon EC2 compute resources. Amazon EC2 (Elastic Compute Cloud) is a web service that provides resizable compute capacity in the cloud. </b><br /><br />Spot Instances enables customers to bid on unused Amazon EC2 capacity and run those instances for as long as their bid exceeds the current &quot;Spot Price&quot; - which changes periodically based on supply and demand. Customers whose bids exceed it gain access to the available Spot Instances. <br /><br />According to the release: &quot;Spot Instances are well-suited for applications that can have flexible start and stop times such as image and video conversion and rendering, data processing, financial modeling and analysis, web crawling and load testing. By being flexible on when their instances run, coupled with the ability to bid what they&rsquo;re willing to pay for capacity, customers can significantly lower their Amazon EC2 costs.&quot;<br /><br />&quot;As customers continued to expand their use of AWS, they started asking if additional pools of capacity were available, even if only for a few hours at a time. Some customers were looking to reduce costs in exchange for being flexible as to when they run their application; others told us they were willing to pay more when they had urgent, high volume needs,&rdquo; said Peter De Santis, General Manger of Amazon EC2. &ldquo;Because of the dynamic nature of supply and demand in the Amazon EC2 environment, we developed Spot Instances to let customers take advantage of our unused capacity while specifying a price they are willing to pay.&quot;</p>
<p>&nbsp;</p>
<hr />
<p>
<img src="http://www.websitemagazine.com/images/blog/wm-pro.gif" style="float:left;margin:3px;" height="41" width="40" alt="" /><b>Stay up to date on the latest Internet trends:</b><br />
Request a professional <a href="http://websitemagazine.com/pro/">subscription to Website Magazine</a>,<br />
the most popular print publication on Web success.</p><div style="clear:both;"></div><img src="http://www.websitemagazine.com/content/aggbug.aspx?PostID=11422" width="1" height="1">amazonamazon ec2ec2spot instances